
87% exploited with the CVE description. Just 7% without it.
The vulnerability didn’t change. The context did.
Research cited in Build Secure or Be Forever Insecure found that GPT-4 exploited 87% of sampled one-day vulnerabilities when given CVE descriptions, compared with just 7% without them. The finding shows how dramatically information can change AI’s ability to reason toward an exploit.
CVE descriptions, advisories, patch diffs, source code and build context aren't useful only to defenders. They can give AI the missing pieces it needs to understand where the weakness is, how it works and how it might be exploited.
In other words, context is becoming an attack accelerant.
Traditional vulnerability management assumes disclosure helps defenders prioritize and remediate. In the AI era, that same disclosure can also accelerate attacker reasoning.
The security clock may no longer start when an exploit is published. It may start when enough context exists for AI to build one.
Organizations need to move beyond asking:
“Is this vulnerability known to be exploited?”
to:
“Could AI turn the context already available into an exploit?”
Build secure before context becomes an attack advantage →